Impact
A remote attacker can send specially crafted SQL statements that target the Db2 Mirror component of IBM i 7.6, 7.5, and 7.4. The flaw allows the attacker to read, insert, modify, or delete database records, compromising confidentiality, integrity, and possibly availability of the application data. The vulnerability is a classic input validation weakness, classified as CWE-89.
Affected Systems
Vendors: IBM. Product: IBM i. Affected versions: 7.6, 7.5, and 7.4. The flaw exists in the Db2 Mirror module across all supported version families of IBM i.
Risk and Exploitability
The CVSS score of 7.6 indicates high severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited documented exploitation but still significant risk. The likely attack vector is remote exploitation: an attacker who can reach the Db2 Mirror interface can construct malicious queries; no local privilege escalation is required. Given the nature of SQL injection, a successful attack could lead to full data compromise if the attacker writes arbitrary queries.
OpenCVE Enrichment